4 ms·
Also, SpiderOak.
by termain 13y ago
Also, SpiderOak.
- JetSpiegel 13y agoI use SpiderOak, but they can still read your files, they hold your keys. Something like tarsnap is the only paranoid-proof choice. It's not even distributed as a binary file. https://www.tarsnap.com/ https://www.tarsnap.com/
- mathrawka 13y agoThey cannot read your files, only your password can be used to decrypt them, which is not even saved on their server. https://spideroak.com/zero-knowledge/ https://spideroak.com/zero-knowledge/ https://spideroak.com/engineering_matters https://spideroak.com/engineering_matters
- LoganCale 13y agoIf you enter your password into a system that they control at any time, they have potential access to your files and can be ordered by the government to change their code so that it does collect your password in order to enable decryption of your files.
- WildUtah 13y agoand can be ordered by the government to change their code so that it does collect your password in order to enable decryption of your files. And they can be ordered to do so secretly with no notice, neither to company management nor to you nor to any judicial body that could review the decision. That's the lesson of Lavabit.
- kelnos 13y ago... or so they say. I do happen to trust them (and use them), but they absolutely could read your files if they want to: all they have to do is release an updated version of the sync app that does save your password when you first sign in. Or they could start saving passwords when people sign in via their website. Now, I don't believe that they'd do this maliciously (rogue employees aside), but there's always the possibility that a government agency could secretly require them to actively try to capture a particular user's password the next time they sign in.
- kenrikm 13y agoI like the concept of SpiderOak and have used them before. However, their software was way too buggy and would stop syncing / working randomly for no apparent reason and their support was unable to help.